Still this: Allow list check error: Target vsys is not specified, user "steven.williams.da" is assumed to be configured with a shared auth profile. Do allow list check before sending out authentication request... User steven.williams.da is not allowed with authentication profile Palo_Alto_Admins ! ! admin@PA500-01> admin@PA500-01> admin@PA500-01> show user group name cn=paloaltoadmins,ou=groups,ou=domain,dc=domain,dc=lan short name: domain\paloaltoadmins source type: ldap source: Domain_Users_and_Groups [1 ] domain\steven.williams.da admin@PA500-01> show user group list cn=paloaltoadmins,ou=groups,ou=domain,dc=domain,dc=lan cn=domain users,cn=users,dc=domain,dc=lan Total: 2 * : Custom Group admin@PA500-01> There has to be a deeper level debug or something to see whats wrong no?
... View more